gram-cli
Fail
Audited by Gen Agent Trust Hub on Jun 26, 2026
Risk Level: HIGHCOMMAND_EXECUTIONCREDENTIALS_UNSAFEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The wrapper script
scripts/run-glam.shdetermines the executable path using theGRAM_CLI_BINenvironment variable. This allows for execution of arbitrary files if the environment variable is manipulated.\n- [COMMAND_EXECUTION]: The scriptscripts/run-glam.shusesexec "$BIN" "$@"which passes all command-line arguments directly to the resolved binary. This can lead to argument injection if the input provided by the agent is not sanitized.\n- [CREDENTIALS_UNSAFE]: Thelogin --print-envcommand explicitly prints raw authentication secrets, including Instagram session IDs and CSRF tokens, to the standard output.\n- [CREDENTIALS_UNSAFE]: The skill accesses sensitive browser data files, specifically Chrome and Firefox cookie databases, to extract authentication information.\n- [EXTERNAL_DOWNLOADS]: The skill is designed to fetch and download data from Instagram's external servers, which are untrusted sources.\n- [PROMPT_INJECTION]: The skill processes untrusted data from Instagram profiles and posts, creating a surface for indirect prompt injection. Malicious instructions embedded in Instagram content could influence the agent's behavior.\n - Ingestion points: profile, post, stories, and highlights commands in
SKILL.md\n - Boundary markers: Absent\n
- Capability inventory: Subprocess calls via
scripts/run-glam.sh\n - Sanitization: Absent
Recommendations
- AI detected serious security threats
Audit Metadata